USN-6989-1: OpenStack vulnerability
4 September 2024
OpenStack could be made to expose sensitive information.
Releases
Packages
- ironic - Openstack bare metal provisioning service - API
Details
Dan Smith, Julia Kreger and Jay Faulkner discovered that in
image processing for Ironic, a specially crafted image
could be used by an authenticated user to exploit undesired behaviors
in qemu-img, including possible unauthorized access to potentially
sensitive data.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.04
Ubuntu 22.04
In general, a standard system update will make all the necessary changes.